// Legal

Privacy Policy

Last updated: June 22, 2026

This Privacy Policy explains what personal data WarmLine (“we”, “us”) collects when you use our LinkedIn outreach software at warmline.io (the “Service”), why we collect it, who we share it with, and the rights you have over it. We act as the data controller for your account data, and as a data processor for the prospect and message data you operate within the Service.

1. Data we collect

  • Account data — your name, email address, and authentication details when you sign up. Passwords are handled by our authentication provider and never stored by us in plain text.
  • Connected-account data — when you connect a LinkedIn account, we process the profile, connection, conversation, and message data needed to run outreach on your behalf, accessed through our sanctioned API provider. We never scrape LinkedIn or operate inside your browser session.
  • Prospect data — names, headlines, company, public profile information, and the buying signals you choose to act on.
  • Billing data — handled by our payment processor (Stripe). We do not store full card numbers.
  • Usage & analytics data — with your consent, we use privacy-respecting product analytics (PostHog) to understand how the Service is used: pages viewed, features clicked, and anonymized device and session information. Input fields and on-screen text are masked in session recordings. No analytics run until you accept the cookie banner.
  • Cookies — strictly-necessary cookies for sign-in and security, plus optional analytics cookies that are set only after you consent.

2. How we use your data

We process personal data to:

  • Provide, operate, and secure the Service and your account.
  • Run outreach you configure, within human-paced sending limits.
  • Process payments and manage your subscription.
  • Improve the product and diagnose issues (analytics — only with consent).
  • Communicate with you about your account, security, and service changes.
  • Comply with our legal obligations.

3. Legal bases (GDPR)

Where the GDPR applies, we rely on: contract (to provide the Service you signed up for), legitimate interests (to secure and improve the Service), consent (for optional analytics cookies, which you can withdraw at any time), and legal obligation (for tax and compliance records).

4. Who we share data with

We do not sell your personal data. We share it only with the sub-processors that run the Service, each bound by data-processing terms:

  • Hosting & database — our cloud hosting and managed Postgres providers (US region).
  • LinkedIn access — our sanctioned LinkedIn API provider.
  • Payments — Stripe.
  • Product analytics — PostHog (US Cloud), only with your consent.
  • Transactional email — our email delivery provider.
  • AI processing — our model provider, used to draft and screen messages.
  • Background job processing — our async workflow provider.

We may also disclose data where required by law, or to protect the rights, safety, and security of WarmLine and its users.

5. International transfers

Our infrastructure is hosted in the United States. Where we transfer data out of the EEA/UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

6. Data retention

We keep personal data for as long as your account is active and as needed to provide the Service. When you close your account, we delete or anonymize your data within a reasonable period, except where we must retain it to meet legal, tax, or security obligations.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing, and to withdraw consent for analytics at any time (use the cookie banner’s Decline option, or clear the consent stored in your browser). To exercise any of these rights, contact us at [email protected]. You also have the right to complain to your local data-protection authority.

8. Security

We use encryption in transit, access controls, and human-paced, ban-safe sending designed to protect your connected accounts. No system is perfectly secure, but we work to protect your data and to notify you of any breach as required by law.

9. Children

The Service is for business use and is not directed to anyone under 18. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, notified to you.

11. Contact

Questions about this policy or your data? Email [email protected].